CVE-2019-3833: High severity centos libwsman1 vulnerability
Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in processconnection() when parsing specially crafted HTTP requests. A remote, unauthenticated attacker can exploit this vulnerability by sending malicious HTTP request to cause denial of service to openwsman server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3833?
CVE-2019-3833 is a vulnerability in Openwsman versions up to and including 2.6.9 that allows an attacker to cause a denial of service by sending specially crafted HTTP requests.
How severe is CVE-2019-3833?
CVE-2019-3833 has a severity score of 7.5, which is considered high.
Which software versions are affected by CVE-2019-3833?
Openwsman versions up to and including 2.6.9 are affected by CVE-2019-3833.
How can the CVE-2019-3833 vulnerability be exploited?
The CVE-2019-3833 vulnerability can be exploited by a remote, unauthenticated attacker by sending malicious HTTP requests.
Are there any references for CVE-2019-3833?
Yes, you can find references for CVE-2019-3833 at the following links: [http://bugzilla.suse.com/show_bug.cgi?id=1122623](http://bugzilla.suse.com/show_bug.cgi?id=1122623), [http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00006.html](http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00006.html), [http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00065.html](http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00065.html).